Cyera Paid $1B Because AI Agents Need Identities. Browser Agents Don't Have One.
Cyera agreed to buy Oasis Security for a billion dollars, and the logic behind that number is funnier than anyone involved would like to admit. Companies are shipping so many AI agents that the agents now need their own onboarding process. Service accounts. OAuth grants. Secrets in a vault with a rotation policy. Somebody has to audit which of the 400 non-human identities in your org still has write access to Salesforce, and apparently that somebody is worth $1B.
Non-human identity management was a niche concern eighteen months ago. Now it’s an acquisition category.
But the whole market rests on an assumption nobody argues with: that an AI agent doing work on your behalf must have its own identity to do it. That’s true for two of the three ways agents currently reach your applications. It is not true for the third.
Three ways an agent gets its hands on your stuff
The cloud agent model is the most common and the most expensive. Your agent runs on someone’s server, so it needs credentials of its own to reach Gmail, Jira, HubSpot, whatever. That means an OAuth app, a consent screen, a refresh token that lives in a database you don’t control, and a permission scope that was chosen once during setup and has been quietly over-broad ever since. Every agent multiplies this. Ten agents, ten identities, ten rotation schedules, ten things to revoke the day someone leaves.
MCP is the polite version. A scoped token for one workspace beats a god-mode service account, and the ecosystem around it has been genuinely good for tool interop, but the token still exists, still sits in a config file, and still outlives the task that justified creating it. I wrote about the ergonomics of this in 40 MCP Tools and It Still Can’t Fill Out a Form. The security shape is the part that matters here: you’ve reduced blast radius without reducing credential count. You still have a thing to leak.
Then there’s the browser. You logged into Gmail this morning. The session cookie is in your Chrome profile, bound to your device, already covered by whatever SSO and MFA policy your company enforces. An agent running inside that tab doesn’t authenticate. It acts as you, in the session you already established, with exactly the permissions you already have.
The credential that doesn’t exist can’t be stolen
Zero new tokens. Zero rotation. Nothing in a vault, nothing in a breach dump, nothing to revoke six months after you forgot it existed.
What “inherits your session” actually means in practice
This is the part people get wrong when they hear it, so let me be specific about the mechanics. Dassi runs as a Chrome extension in the side panel. When it drafts a reply in your inbox, it isn’t calling the Gmail API with a token it obtained through a consent flow. It’s reading the DOM of the tab you have open and typing into the compose box, the same way you would, inside the session Google already trusts because you authenticated to it with your hardware key twenty minutes ago.
The security consequences fall out of that mechanically. Your admin’s session timeout applies to the agent, because it’s the same session. Conditional access policies apply, because the requests originate from your device. If IT kills your account at 4pm, the agent is dead at 4:01, without anyone remembering to go find a service account and disable it. There is no separate audit trail to reconcile, because the actions show up in your normal Google audit log as you, from your IP, in your browser.
Compare that to the cloud agent, where the audit log says a request came from an AWS IP in us-east-1 belonging to an OAuth app your marketing team authorized in March. Good luck telling a real breach from Tuesday.
And the failure modes are different in a way that matters. A leaked OAuth refresh token works from anywhere, silently, until someone notices. A stolen browser session is a much worse asset for an attacker, because it’s already scoped to one device, one profile, one timeout window, sitting behind whatever endpoint controls you run.
The honest cost
Browser-native execution buys this by giving something up. The agent only works when your browser is open and you’re at your machine. No 3am scheduled runs, no headless fleet churning through 10,000 records overnight. If your workload genuinely needs that, you need a service account, and you need someone like Oasis to keep track of it.
Most people’s actual work is not that workload. It’s inbox triage, form filling, pulling numbers out of an admin panel that has no export button, the stuff in Your AI Browser Agent Can’t See That You’re Logged In. All of it happens in tabs you already have open, during hours you’re already awake.
So the billion-dollar problem is real, and the identity sprawl is real, and the fix for a large chunk of it is embarrassingly boring: stop issuing credentials to agents that could just borrow yours. Dassi is free on the Chrome Web Store, and it never asks for a Google login, because it doesn’t need one.
Somewhere there’s a security team about to spend a quarter building governance for agents that shouldn’t have had identities in the first place. Hell of a way to find out.